Custom Open-Source CVD Platform

Employer not named by the sourceRemote

Full Stack

Apply on the company’s site

Frontier is not the employer and does not collect applications.

About this role

PHP, Linux, Software Architecture, MySQL, Docker, Web Development, Open Source, Ansible · I need a Coordinated Vulnerability Disclosure system built entirely from open-source components and delivered as software only—no appliances or proprietary add-ons. The core feature I must have is a robust workflow for tracking and managing reported vulnerabilities, from initial submission through resolution and disclosure.

The application has to run smoothly on a Linux server, so please choose libraries and frameworks that are well supported in that environment. For user access, multi-factor authentication is mandatory; I want researchers, internal engineers, and any third-party responders to sign in with something stronger than a simple password.

You are free to select or combine existing open-source projects (for example, Bug Bounty platforms, ticketing systems, or secure messaging stacks) as long as the final product offers:

• A clean web interface for submitting, updating, and viewing vulnerability tickets • Role-based access so different stakeholders can see only what they need • An audit trail for every action taken on a report • Secure data storage with encryption for sensitive attachments and notes

Hand-over items: source code in a public or private repo, a o